CVE-2026-19038: Path Traversal in MonomythDevelopment la-forge-mcp
CVE-2026-19038 is a path traversal vulnerability in MonomythDevelopment la-forge-mcp version 1.0.0. It affects the screenshotElement function in the src/index.ts file of the screenshot_element tool component. The vulnerability allows remote attackers to manipulate the output_name argument to perform path traversal. The issue is fixed in version 1.1.1.
AI Analysis
Technical Summary
This vulnerability in MonomythDevelopment la-forge-mcp 1.0.0 involves improper handling of the output_name argument in the screenshotElement function, leading to a path traversal flaw. This allows an attacker to potentially access or overwrite files outside the intended directory. The vendor responded promptly and released version 1.1.1 to address the issue with patch 1102172c9adec4a619e241efd6bfb74f5b1f4332.
Potential Impact
The vulnerability enables remote attackers to perform path traversal via the output_name argument, which could lead to unauthorized file access or modification. The CVSS 4.0 score is 5.3 (medium severity), indicating a moderate impact with network attack vector, low complexity, no privileges required, and no user interaction needed.
Mitigation Recommendations
Upgrade to la-forge-mcp version 1.1.1, which contains the official fix for this vulnerability. The vendor has released this fixed version promptly after being contacted.
CVE-2026-19038: Path Traversal in MonomythDevelopment la-forge-mcp
Description
CVE-2026-19038 is a path traversal vulnerability in MonomythDevelopment la-forge-mcp version 1.0.0. It affects the screenshotElement function in the src/index.ts file of the screenshot_element tool component. The vulnerability allows remote attackers to manipulate the output_name argument to perform path traversal. The issue is fixed in version 1.1.1.
CVSS v4.0
Score 5.3medium
Affected software
pkg:github/monomythdevelopment/la-forge-mcpcpe:2.3:a:monomythdevelopment:la-forge-mcp:*:*:*:*:*:*:*:*Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in MonomythDevelopment la-forge-mcp 1.0.0 involves improper handling of the output_name argument in the screenshotElement function, leading to a path traversal flaw. This allows an attacker to potentially access or overwrite files outside the intended directory. The vendor responded promptly and released version 1.1.1 to address the issue with patch 1102172c9adec4a619e241efd6bfb74f5b1f4332.
Potential Impact
The vulnerability enables remote attackers to perform path traversal via the output_name argument, which could lead to unauthorized file access or modification. The CVSS 4.0 score is 5.3 (medium severity), indicating a moderate impact with network attack vector, low complexity, no privileges required, and no user interaction needed.
Mitigation Recommendations
Upgrade to la-forge-mcp version 1.1.1, which contains the official fix for this vulnerability. The vendor has released this fixed version promptly after being contacted.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-08-06T05:53:43.123Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a748820bf8831d539bf1b85
Added to database: 08/06/2026, 13:12:00 UTC
Last enriched: 08/06/2026, 13:32:03 UTC
Last updated: 08/06/2026, 13:46:18 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.